VDB

DEBIAN-CVE-2016-1000341

DEBIAN-CVE-2016-1000341 PUBLISHED CVSS 5.900000095367432 MEDIUM

In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack. Where timings can be closely observed for the generation of signatures, the lack of blinding in 1.55, or earlier, may allow an attacker to gain information about the signature's k value and ultimately the private value as well.

Risk Scores

CVSS v3.0
5.900000095367432
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Debian:11bouncycastle0, 0, 0
Debian:14bouncycastle0, 0, 0
Debian:13bouncycastle0, 0, 0
Debian:12bouncycastle0, 0, 0

Exploit Intelligence

Timeline

  • Jun 4, 2018 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›